Skip to content

Commit 396a054

Browse files
authored
Remove iam:PassRole permission from Task handler (#26)
This is not necessary for creating tasks.
1 parent 58f453f commit 396a054

File tree

2 files changed

+2
-5
lines changed

2 files changed

+2
-5
lines changed

aws-datasync-task/aws-datasync-task.json

Lines changed: 2 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -320,8 +320,7 @@
320320
"elasticfilesystem:DescribeFileSystems",
321321
"elasticfilesystem:DescribeMountTargets",
322322
"logs:DescribeLogGroups",
323-
"iam:GetRole",
324-
"iam:PassRole"
323+
"iam:GetRole"
325324
]
326325
},
327326
"read": {
@@ -349,8 +348,7 @@
349348
"fsx:DescribeFileSystems",
350349
"elasticfilesystem:DescribeFileSystems",
351350
"elasticfilesystem:DescribeMountTargets",
352-
"iam:GetRole",
353-
"iam:PassRole"
351+
"iam:GetRole"
354352
]
355353
},
356354
"list": {

aws-datasync-task/resource-role.yaml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -41,7 +41,6 @@ Resources:
4141
- "elasticfilesystem:DescribeMountTargets"
4242
- "fsx:DescribeFileSystems"
4343
- "iam:GetRole"
44-
- "iam:PassRole"
4544
- "logs:DescribeLogGroups"
4645
- "s3:ListAllMyBuckets"
4746
- "s3:ListBucket"

0 commit comments

Comments
 (0)